Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Sr Product Security Engineer, SSDL image - Rise Careers
Job details

Sr Product Security Engineer, SSDL - job 1 of 2

Company Description

It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today — ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500®. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone.

Job Description

Team

Product Security is Shifting Everywhere and holistically improving the maturity of the security program. The Secure Software Development Lifecycle (SSDL) team helps the organization measure and improve security activities. The team leads product threat modeling, helps to improve security behaviors, and manages a highly visible security champions program. The team is both highly technical and strategic.

Role

As a Senior Product Security Engineer on the ServiceNow SSDL team, you will collaborate with developers and software architects on highly technical solutions and help the organization build secure and resilient software. You will be threat modeling software products and services to identify potential risk and participate in architectural reviews of products in development.

A key part of this position is to ensure the continued success of a large and growing security champions program. You will help mentor security champions and assist them in secure software design. As a Senior Product Security Engineer, you will help security champions be successful.

What you get to do in this role:

  • Work on a wide range of technologies
  • Work on complex architectural and technical challenges
  • Participate in threat modeling activities
  • Mentor and collaborate with development teams to adopt secure coding practices
  • Work on strategic and highly visible security activities across the organization
  • Be an advocate for security and participate in a security champions program

Qualifications

To be successful in this role you have:

  • Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI's potential impact on the function or industry.
  • 4+ years of experience in software security (AppSec)
  • 1+ years of experience in threat modeling software applications and services
  • Proficient in threat modeling methodologies such as STRIDE or PASTA and their applied use in fast-moving, iterative development lifecycles
  • In-depth knowledge of common web application vulnerabilities (OWASP Top 10)
  • Developer-level proficiency in one or more languages - Python, Java, JavaScript, and Golang preferred
  • Knowledge in authentication and authorization standards including OAuth, OIDC, SAML, JWT, and PASETO
  • Knowledge of symmetric and asymmetric cryptography, digital signatures, PKI, TLS, and cryptographic hash functions
  • Knowledge of cloud native technologies including containers, Kubernetes, and services provided by AWS, GCP, and Azure
  • Knowledge of static analysis (SAST), dynamic analysis (DAST), and software composition analysis (SCA) security tools
  • Knowledge of OWASP ASVS, SCVS, and related verification standards
  • Ability to work collaboratively in a highly distributed team
  • Ability to communicate technical concepts to business stakeholders
  • A passion for security

 

JV20

Not sure if you meet every qualification? We still encourage you to apply! We value inclusivity, welcoming candidates from diverse backgrounds, including non-traditional paths. Unique experiences enrich our team, and the willingness to dream big makes you an exceptional candidate!

Additional Information

Work Personas

We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work. Learn more here.

Equal Opportunity Employer

ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements. 

Accommodations

We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact [email protected] for assistance. 

Export Control Regulations

For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities. 

From Fortune. ©2024 Fortune Media IP Limited. All rights reserved. Used under license. 

ServiceNow Glassdoor Company Review
4.5 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
ServiceNow DE&I Review
4.6 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of ServiceNow
ServiceNow CEO photo
Bill McDermott
Approve of CEO

Average salary estimate

$140000 / YEARLY (est.)
min
max
$120000K
$160000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Sr Product Security Engineer, SSDL, ServiceNow

Are you ready to take on a pivotal role as a Senior Product Security Engineer at ServiceNow in Hyderabad? Here, you'll be at the heart of our Secure Software Development Lifecycle (SSDL) team, a group dedicated to transforming the way security integrates with our dynamic development processes. Collaborating closely with developers and software architects, your expertise will help identify potential risks and promote secure coding practices across our product line. You'll engage in meaningful activities such as threat modeling and architectural reviews, ensuring that we build resilient software while nurturing a robust security champions program. If you have a passion for mentoring and advocating for security, this is your chance to shape technical solutions and influence a culture that prioritizes security. With your experience in software security and knowledge of web vulnerabilities, you will guide developers towards secure practices and play a vital role in the ongoing success of our security initiatives. At ServiceNow, you won’t just work on complex challenges; you’ll also be part of a mission to make the world work better for everyone. Join us in transforming tech with innovative solutions, and let’s pave the path towards a secure future together.

Frequently Asked Questions (FAQs) for Sr Product Security Engineer, SSDL Role at ServiceNow
What are the responsibilities of a Senior Product Security Engineer at ServiceNow?

As a Senior Product Security Engineer at ServiceNow, you will focus on collaborating with development teams to improve security practices. Your responsibilities include leading threat modeling activities, participating in architectural reviews, mentoring security champions, and advocating for secure coding. You'll also work on various strategic security initiatives, helping to enhance the security posture across development operations.

Join Rise to see the full answer
What qualifications are needed for the Senior Product Security Engineer role at ServiceNow?

To qualify for the Senior Product Security Engineer position at ServiceNow, you should have at least 4 years of experience in software security, and a minimum of 1 year of experience in threat modeling. Familiarity with methodologies like STRIDE or PASTA, knowledge of OWASP Top 10 vulnerabilities, and proficiency in programming languages such as Python or Java are also essential.

Join Rise to see the full answer
How does the Senior Product Security Engineer contribute to threat modeling at ServiceNow?

In the role of Senior Product Security Engineer at ServiceNow, you'll play a crucial part in threat modeling by identifying and analyzing potential risks associated with software products. By collaborating with developers during this process, you’ll help ensure that security measures are integrated into the software development lifecycle, enhancing the overall security architecture.

Join Rise to see the full answer
What technologies should a Senior Product Security Engineer at ServiceNow be familiar with?

A Senior Product Security Engineer at ServiceNow should have knowledge of cloud-native technologies, including containers and Kubernetes, along with experience in using security tools like static analysis (SAST) and dynamic analysis (DAST). Familiarity with authentication standards, cryptography, and security verification standards such as OWASP ASVS is also highly beneficial.

Join Rise to see the full answer
What is the work environment like for a Senior Product Security Engineer at ServiceNow?

At ServiceNow, the work environment for a Senior Product Security Engineer is collaborative and highly flexible. You will join a distributed team that values inclusivity and innovation, actively fostering a culture where team members can contribute to significant security initiatives while working on complex architectural challenges.

Join Rise to see the full answer
Common Interview Questions for Sr Product Security Engineer, SSDL
Can you explain your experience with threat modeling methodologies like STRIDE or PASTA?

In your response, you should discuss your familiarity and practical experience using these methodologies. Highlight specific projects where you have successfully implemented threat modeling, explaining how it helped identify vulnerabilities and mitigate risks.

Join Rise to see the full answer
What steps would you take to mentor a security champion on secure software practices?

Outline a structured approach where you assess the current knowledge of the security champion, provide training on secure coding practices, and establish ongoing support and resources. Mention the importance of encouragement and feedback in fostering a security-first mindset.

Join Rise to see the full answer
How do you stay updated with the latest security vulnerabilities and trends?

Share various resources you use to stay informed, such as security newsletters, blogs, forums, or community events. Emphasize the value of continuous learning and how you apply this knowledge in your role as a security engineer.

Join Rise to see the full answer
What web application vulnerabilities do you find most concerning, and why?

Discuss specific vulnerabilities from the OWASP Top 10, emphasizing the potential impact each has on security. Provide real-world examples or case studies to illustrate your understanding and the importance of addressing these vulnerabilities.

Join Rise to see the full answer
How would you approach a security audit of a new application?

Explain your process for conducting a security audit, including threat modeling, vulnerability scanning, and collaborating with developers. Stress the importance of a thorough review and the need for clear communication of findings and recommendations.

Join Rise to see the full answer
What role does automation play in your security processes?

Discuss how you utilize automated tools for tasks like static and dynamic analysis, and how these tools effectively enhance your workflow. Include examples of how automation has improved your efficiency or increased the accuracy of your security assessments.

Join Rise to see the full answer
Describe a challenging security issue you faced and how you resolved it.

Share a specific example that illustrates your problem-solving skills and technical expertise. Describe the situation in detail, the steps you took to resolve it, and the positive outcome that resulted from your actions.

Join Rise to see the full answer
How do you ensure that security considerations are integrated into the software development lifecycle?

Detail how you engage with different teams throughout the development process, from requirements gathering to deployment. Highlight strategies like threat modeling workshops and security reviews to ensure security remains a priority.

Join Rise to see the full answer
What would you include in a security training program for developers?

Outline key components that should be taught, such as secure coding practices, awareness of common vulnerabilities, and the importance of integrating security early in development. Tailor your response to reflect what you believe to be the most impactful training methods.

Join Rise to see the full answer
How do you communicate technical security concepts to non-technical stakeholders?

Emphasize your ability to simplify complex concepts using analogies or visual aids. Explain how facilitating discussions and providing relatable examples are key to ensuring stakeholders understand security implications related to their work.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
ServiceNow Remote Salarpuria Sattva Knowledge City Knowledge City, Unit II, 17 to 10 Floor Survey No. 83/1, Serilingampally Mandal, Hyderabad, India
Posted 21 hours ago
Inclusive & Diverse
Mission Driven
Rise from Within
Diversity of Opinions
Work/Life Harmony
Empathetic
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Conferences Stipend
Paid Time-Off
Maternity Leave
Equity

Become a key figure in securing access for millions as a Product Manager at ServiceNow, shaping global authentication solutions.

Photo of the Rise User
ServiceNow Remote Remote , New York , New York , United States
Posted 21 hours ago
Inclusive & Diverse
Mission Driven
Rise from Within
Diversity of Opinions
Work/Life Harmony
Empathetic
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Conferences Stipend
Paid Time-Off
Maternity Leave
Equity

ServiceNow is looking for a Technology Industry GTM Lead to enhance business strategies and relationships with top technology clients remotely.

Photo of the Rise User
American Express Remote Phoenix, Arizona, United States
Posted 4 days ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

As a Mid-Level Associate in Digital Product Operations at American Express, you'll lead vital connectivity projects to enhance customer transactions on a global scale.

Photo of the Rise User

Join Delivery Hero as the Director of Product Management to shape customer experiences for millions of users across various platforms.

Photo of the Rise User

Lead the product strategy for provider-facing Customer Experience products at GeneDx, enhancing usability and satisfaction for healthcare providers in a fully remote role.

Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Take Risks
Casual Dress Code
Startup Mindset
Emails over Meetings
Collaboration over Competition
Fast-Paced
Growth & Learning
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Mixe-Ability Accomodations
Work Visa Sponsorship
Commuter Benefits
Employee Resource Groups
Performance Bonus
Health Savings Account (HSA)
Flexible Spending Account (FSA)

Become a vital component of TikTok's growth strategy as a Partner Manager, specializing in building partnerships within key verticals to unlock advertising innovations.

Photo of the Rise User

Join Cover Genius as an Insurance Product Manager / Underwriter and play a key role in shaping innovative insurance solutions for global partners.

Toyota Remote Toyota Canada Inc - Head Office
Posted 22 hours ago

Join Toyota Canada as a Product Planning Analyst and play a pivotal role in shaping the future of automotive products for the Canadian market.

Photo of the Rise User
Posted 5 days ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Take the lead in driving product development and strategy at American Express as a Senior Manager of Digital Product Management in New York.

Photo of the Rise User
Posted 13 days ago

Join Flipp as a Senior Product Manager and lead the charge in transforming the digital shopping landscape through innovative product strategies.

We're on a mission to become the defining enterprise software company of the 21st century.

2180 jobs
MATCH
Calculating your matching score...
CULTURE VALUES
Inclusive & Diverse
Mission Driven
Rise from Within
Diversity of Opinions
Work/Life Harmony
Empathetic
Feedback Forward
Take Risks
Collaboration over Competition
BENEFITS & PERKS
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Conferences Stipend
Paid Time-Off
Maternity Leave
Equity
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 12, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Cleveland just viewed Event Specialist at Marble Room
Photo of the Rise User
Someone from OH, Youngstown just viewed Director, Clinical Informatics at Ro
Photo of the Rise User
Someone from OH, Dayton just viewed Shopify Specialist at Remote VA
L
Someone from OH, Dayton just viewed Mechanical Design Engineer(s) at LTTS
H
Someone from OH, Akron just viewed Financial Content Writer at Huntington
W
Someone from OH, Columbus just viewed Director of Regulatory Compliance - WEX Bank at WEX Inc